Skip to content

Legal

Privacy Policy

Effective date: 16 August 2026

Last updated: 10 September 2026

Version: 3.2

HUDOOD FINTECH PRIVATE LIMITED (CIN U66190MH2024PTC436439), a private limited company incorporated in India on 14 December 2024, operates the Hudood community and market-data service ("Hudood", "we", "us"). This policy explains what personal data Hudood handles, why it is used, who receives it, how long it is kept, and the choices available to you.

Hudood is intended only for people aged 18 or over.

1. Contact

  • Email: legal@hudood.com
  • Telephone: +91 88288 88664
  • Correspondence address: HD-706, WeWork, Vaswani Chambers, Prabhadevi Road, Government Colony, Mumbai, Maharashtra 400051, India
  • Website: https://hudood.com

For a privacy request, use the subject Privacy Request. For an Indian intermediary grievance, see the Grievance Redressal Policy.

2. Data we handle

Depending on how you use Hudood, we handle:

  • Account and identity data: name, username, email address, date of birth or age-confirmation data, gender, profile image, hashed password, login/provider identifiers, device sessions, and account status. A telephone number is handled only if you previously or optionally supplied one; the current sign-up flow does not require it.
  • Profile data: biography, location, interests, education, work, selected net-worth range, website links, and other profile fields you choose to publish.
  • Community content: posts, captions, comments, reactions, follows, saved items, photos, videos, reels, messages, reports, appeals, and associated timestamps and metadata.
  • Finance preferences: watchlists, portfolios, selected instruments, and market-data interactions. At initial launch Hudood does not publish HALAL or HARAM verdicts and does not sell Premium.
  • Usage and recommendation data: screens and content viewed, watch time or dwell time, searches, clicks, interactions, and recommendation or moderation events.
  • Device and technical data: IP address, browser or device type, operating system, app version, language, push-notification token, security events, crash diagnostics, and performance traces.
  • Support and compliance data: correspondence, grievance records, reports, evidence supplied by a reporter, moderation decisions, appeals, deletion requests, legal requests, and audit events.

Hudood receives this data from you, your device, your interactions with the service, other users who report content, authentication providers you choose, and the service providers listed below.

3. Passwords and sign-in

When you create or use an email-and-password account, Hudood's server receives the password transiently to create or verify a cryptographic hash. Hudood stores the hash, not the raw password. Firebase Authentication may also receive account identifiers and authentication/session data to bridge identity across the web and mobile apps. If a third-party sign-in option is offered, that provider supplies an account identifier and the profile data you authorize.

4. Why we use data

We use personal data to:

  • create, authenticate, secure, and administer accounts;
  • publish the profile and community content you choose to share;
  • deliver feeds, search, messages, notifications, market data, watchlists, and portfolios;
  • personalize and measure recommendations and product performance;
  • prevent spam, fraud, abuse, account compromise, and unlawful content;
  • receive, investigate, and resolve reports, grievances, appeals, deletion requests, and legal requests;
  • maintain evidence, logs, backups, and audit records needed for security and legal compliance;
  • communicate material service, safety, and policy notices; and
  • establish, exercise, or defend legal claims.

Where applicable law requires a legal basis, these activities rely on performance of our agreement with you, legitimate interests in operating and protecting Hudood, compliance with legal obligations, consent where specifically requested, or protection of vital interests in an emergency.

5. Public and private information

Profile fields and community content marked public can be seen, copied, or shared by other people. Direct messages, non-public portfolio information, reports, and account-security data are not public, but may be accessed by authorized personnel and processors when necessary to operate, secure, or moderate the service or comply with law.

Do not publish financial account credentials, government identifiers, health records, or other sensitive information in public content.

6. Service providers and disclosures

Hudood uses processors for hosting, storage, authentication, notifications, diagnostics, translation, market-data delivery, email, app distribution, and security. The current provider categories and purposes are listed in the Data Processing and Sub-Processor Register.

Personal data may also be disclosed:

  • to a person you direct us to share it with;
  • to authorities or courts when required by valid law or legal process;
  • when reasonably necessary to protect a person, investigate abuse, or secure Hudood;
  • in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice; or
  • in aggregated or de-identified form that is not reasonably linkable to you.

Hudood does not sell personal data and does not use third-party advertising trackers at initial launch.

Crash reporting starts when the app opens, before you have an account, and you should know that rather than discover it. Our error-monitoring provider is initialised at launch so that a crash on the sign-in screen is reported at all — a fault that stops people creating an account is precisely the one we would otherwise never see. What it collects is a stack trace and technical context about the fault, attributed to a device and a session; before you sign in there is no account for it to be attributed to, and after you sign in it carries your user identifier only when an error occurs. It is not analytics: nothing records which screens you visited, how long you stayed, or what you tapped. We rely on our legitimate interest in keeping the service working, and you can stop it entirely by not using the app.

7. International processing and transfers

Hudood is an India-first service. It is not offered in the European Economic Area, the United Kingdom or Switzerland - see section 7B. Most of our users are in India, and Hudood's primary application and database hosting is configured in Microsoft Azure's Central India region. Some providers operate global infrastructure and may process data outside your state or country. We use contractual and technical protections appropriate to the service and applicable law, but no internet or storage system can be guaranteed completely secure.

7A. Legal bases (EEA, UK and Switzerland)

Hudood is not offered in those territories (section 7B). Where the EU or UK General Data Protection Regulation nonetheless applies to you, we rely on the following legal bases under Article 6(1):

What we doLegal basis
Create and operate your account, deliver posts, comments and messages you ask us to deliverContract - Article 6(1)(b)
Keep the service secure: abuse prevention, rate limiting, fraud and spam controls, audit recordsLegitimate interests - Article 6(1)(f), in running a safe service
Show market data, charts and catalogue informationContract and legitimate interests
Push notifications you have switched onConsent - Article 6(1)(a), withdrawable at any time in settings
Respond to grievances, law-enforcement requests, and copyright noticesLegal obligation - Article 6(1)(c), and legitimate interests
Retain limited records after deletion where the law requires itLegal obligation

Hudood does not use your personal data for advertising profiling, does not sell personal data, and does not make decisions producing legal or similarly significant effects about you by automated means alone. Moderation decisions that restrict an account are reviewable by a person on request.

7B. European Economic Area, United Kingdom and Switzerland

Hudood is not offered in the European Economic Area, the United Kingdom or Switzerland. The service is not distributed through app stores in those territories and is not marketed to people there.

Article 27 of the EU GDPR and of the UK GDPR requires a controller established outside those territories, and offering services to people inside them, to designate a written representative there. The Swiss Federal Act on Data Protection carries its own representative requirement. Because Hudood does not offer the service in any of the three, no representative is designated. We will designate one, and publish the representative's name and address in this section, before making the service available there.

If you are in the EEA, the United Kingdom or Switzerland and believe Hudood holds personal data about you - for example because you installed Hudood before this position took effect - contact the Grievance Officer in section 1. Your rights under section 9 will be honoured regardless.

8. Retention and deletion

We keep data only for the purpose and period described below, unless a valid legal hold or longer legal obligation applies:

DataNormal period
Active account, profile, content, messages, watchlists and portfoliosWhile the account is active or until you delete the item, subject to safety and legal exceptions
Deactivated account awaiting deletion30-day recovery period; public profile and content are hidden immediately
Registration information required by Rule 3(1)(g) of India's IT Rules180 days after account cancellation or withdrawal, then erased unless another legal duty applies
Content removed or disabled under Rule 3(1)(h) of India's IT Rules, and its associated records180 days for investigation, or longer only if lawfully required
Routine pseudonymous moderation/compliance events after account scrubUp to 180 days, because these records include a hashed and encrypted IP address and CERT-In Direction 20(3)/2022 requires such logs to be kept for 180 days
High-risk hashed abuse, fraud, or security signals after account scrubUp to 180 days
Application and security logsNormally up to 180 days where required for cyber-security compliance; shorter where operationally sufficient
Reports, grievances and legal-request recordsFor the investigation and any legally required limitation, audit, or preservation period
Azure database backupsUp to 35 days under the configured backup schedule

After the 30-day recovery period, Hudood scrubs the canonical user record, removes public content attribution, starts deletion at active processors, and records completion. A legal hold must identify its reason, authority, approver, start date, and expiry or review date.

Backups are the one place erasure is not immediate, and we would rather say so than imply otherwise. Your data is erased from live systems as described above, and disappears from database backups within 35 days as those backups expire on their rolling schedule. Backups cannot be edited selectively — no database platform supports removing one person from a historical snapshot without destroying the snapshot's integrity — so the honest description is expiry rather than surgical deletion. During that window the data is encrypted at rest and is not used for any purpose other than restoring the service after a failure.

Retention required by law can outlast a deletion request, and this is the one limit on erasure worth stating plainly. Where Rule 3(1)(g) or Rule 3(1)(h) of India's IT Rules requires us to keep registration information or removed content for 180 days, we keep it for that period and no longer, and we keep only what the rule names — the fact that an account existed and was cancelled, not the content you created. Everything outside that record is erased on the ordinary schedule.

See the Data-Deletion Policy for the request process and detailed effects.

9. Your choices and rights

You can update many profile fields, change privacy settings, control notifications, delete individual content, block users, and request account deletion within Hudood. You may also ask us to:

  • provide access to or a copy of your personal data;
  • correct inaccurate data;
  • erase data that we are not required to retain;
  • withdraw consent for a consent-based activity;
  • explain or review an account or moderation decision; or
  • identify the grievance route available to you.

To make a request, either use Help & support in the Hudood app or Settings → Contact support on the website and choose Privacy or your data, or email legal@hudood.com with the subject Privacy Request. The in-product route gives you a reference and a thread you can reply on; the email route remains open and is not second class.

Requests made through the in-product route carry a 30-day clock, which is the same one-month period committed to below and the period the product itself enforces on the request.

We may verify your identity and may refuse or limit a request where law permits, including to protect another person's rights, investigate abuse, preserve evidence, or comply with a retention duty.

India's Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 have phased commencement dates. Hudood applies the controls described here as service commitments; statutory rights and duties apply when and to the extent brought into force.

If the EU or UK GDPR applies to you, you also have the right to restrict processing, to object to processing based on legitimate interests, and to receive the data you provided in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible. You may withdraw consent at any time without affecting processing already carried out. We answer requests within one month, extendable by two further months for complex requests, and we will tell you if we need the extension.

You may lodge a complaint with your local supervisory authority. In the EEA that is the data protection authority of your country of residence, work, or the place of the alleged infringement; in the UK it is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.

If you are in California, you may request access to, deletion of, and correction of personal information, and you may request details of the categories collected, used, and disclosed. Hudood does not sell or share personal information for cross-context behavioural advertising, so no opt-out of sale is required. We will not discriminate against you for exercising these rights.

Everywhere else, the rights listed above are offered as service commitments, whether or not your local law requires them.

10. Security

Hudood uses access controls, password hashing, transport encryption, separated runtime credentials, security logging, moderation controls, and deletion audit trails. You are responsible for protecting your device and account credentials and for notifying us promptly of suspected compromise.

11. Children

Hudood does not permit accounts for anyone under 18. If you believe a minor has created an account or child sexual abuse material is present, report it immediately through the in-app report flow or email admin@hudood.com with the subject Child Safety - Urgent. See the Child Safety Standards.

12. Changes

We may update this policy when the service, providers, or law changes. We will publish the new date and provide any notice required by law. Material changes do not retroactively reduce rights already granted without a lawful basis.